Legal

Privacy Policy

This Privacy Policy explains how Varazm collects, uses, stores and protects the personal information you share with us through our website, bookings, payments and IT services. We follow the UK GDPR and the Data Protection Act 2018.

Last updated 13 July 2026
01

Who we are

Varazm ("Varazm", "we", "us", "our") is an IT services provider operating in the United Kingdom and trading through www.varazm.com. For all personal information you submit through this website, the AEO Analyzer, our bookings, our payment flows and our support channels, Varazm is the data controller under the UK GDPR.

If you have any question about this policy or about how we handle your information, you can reach us at support@varazm.com.

02

Information we collect

We only collect information that we genuinely need to provide and improve our services. Depending on how you interact with us, this may include:

  • Account data — email address, display name and hashed password when you register an account (for the AEO Analyzer or a booking), plus the timestamps of your sign-in activity for security monitoring.
  • Identity & contact data — full name, business name, email, phone or WhatsApp number, and postal address when you contact us, book a consultation or sign a service agreement.
  • Booking & service data — the service you selected, preferred date and time, the device or system in question, notes you share with us, and any access information you choose to provide for support.
  • AEO Analyzer data — the URLs you submit for analysis, the publicly accessible HTML/metadata we fetch from those URLs, the scan results, the AI-generated recommendations, downloadable PDF reports, your scan credit balance and your subscription status.
  • Payment data — the payment itself is processed by our regulated payment provider (Stripe). We do not see or store your full card number, CVV or banking credentials. We keep limited transaction information (amount, currency, date, last 4 digits, invoice number, payment status, Stripe customer / subscription IDs) so we can issue receipts and branded PDF invoices, handle refunds and keep proper accounting records.
  • Reviews & feedback — when you submit a review, we store your name, email, invoice number, rating and review content so we can verify and display it (after admin approval).
  • Technical & security data — IP address, browser type and version, language, device type, referring page and pages visited, along with rate-limit counters used to prevent brute-force attempts and abuse.
  • Communications — emails, WhatsApp messages, contact forms and support tickets, so we can answer you and keep a record of what was agreed.
03

How we use your information (and our legal basis)

We rely on one of the following UK GDPR legal bases each time we use your information:

  • Contract — to create and manage your account, deliver AEO scans and subscriptions, quote and deliver IT services, take payment and provide aftercare.
  • Legitimate interests — to keep our website, AEO Analyzer and infrastructure secure, prevent fraud, credential stuffing and abuse (including rate-limits and password-breach checks against the Have I Been Pwned database), improve our services and respond to enquiries.
  • Legal obligation — to keep tax, accounting, invoicing and consumer-rights records required by UK law (typically for 6 years).
  • Consent — for any optional marketing email or non-essential cookie. You can withdraw consent at any time without affecting service delivery.
04

AEO Analyzer & AI processing

When you use the AEO Analyzer, we automatically fetch the URL you submit as a normal HTTP request would. We then process the publicly available response to compute an "answer-engine readiness" score and to produce written recommendations. To do so:

  • We send extracted structured content (headings, meta tags, schema markup, key text snippets) to trusted AI model providers acting as our processors, including Google (Gemini), OpenAI and other engines routed through the Lovable AI Gateway.
  • These providers process the content on our behalf under contractual data-processing terms and are instructed not to train their models on it.
  • We do not submit your account email, payment details or any of your other private data to the AI models — only the public content of the URL you asked us to analyse and a minimal request identifier.
  • Generated PDF reports are stored in your account and can be deleted by you at any time from the Reports tab of your account page.
05

Payments & subscriptions

All online payments on this website are processed by Stripe, a PCI-DSS compliant payment processor. When you pay for a single AEO scan, a premium AEO subscription or an IT service:

  • Card details are entered directly into Stripe's secure form and are never sent to or stored on Varazm's servers.
  • We receive a confirmation including the amount, currency, payment status and a Stripe reference, which we link to your invoice, subscription and account.
  • For subscriptions we also store the Stripe customer and subscription identifiers, the current period end and cancel-at-period-end flag so you can manage or cancel your plan directly from your account page without contacting us.
  • Refunds, chargebacks and disputes are handled in line with UK consumer law and the terms agreed in your service contract.
  • We keep payment records for at least six (6) years to comply with HMRC and accounting requirements.
06

Sharing your information

We never sell your personal data. We share it only with carefully selected processors who help us run the business under written contracts and confidentiality obligations, including:

  • Cloud hosting, database, email and object-storage infrastructure providers.
  • Stripe, for processing payments and hosting the subscription billing engine.
  • AI model providers routed through the Lovable AI Gateway (e.g. Google Gemini, OpenAI) for AEO analysis and the AI Advisor.
  • Have I Been Pwned (HIBP), when a hashed prefix of a new password is checked against known breaches (no full password is ever sent).
  • Communication tools (e.g. WhatsApp Business) when you choose to contact us through them.
  • Professional advisers (accountants, lawyers, insurers) where strictly necessary.
  • UK authorities or regulators where we are legally required to disclose information.
07

International transfers

Some of our providers are based outside the United Kingdom or the European Economic Area. Whenever your data is transferred internationally, we make sure it is protected by appropriate safeguards such as the UK International Data Transfer Agreement, the EU Standard Contractual Clauses or an adequacy decision.

08

How long we keep your information

  • Account records: for the lifetime of your account plus 24 months after deletion or last activity.
  • AEO scan reports: kept in your account until you delete them; we may also delete very old anonymous scans after 24 months.
  • Enquiries and unsuccessful quotes: up to 24 months.
  • Active client records and service tickets: for the duration of our relationship plus 24 months.
  • Invoices, payments and accounting records: at least 6 years (UK statutory requirement).
  • Reviews and testimonials: until you ask us to remove them.
  • Server logs and security data: typically up to 12 months.
09

Your rights under UK GDPR

You have the right to:

  • Access the personal data we hold about you.
  • Ask us to correct inaccurate or incomplete information — most profile fields can be edited yourself from your account page.
  • Ask us to erase your data where it is no longer needed.
  • Restrict or object to certain uses of your data.
  • Receive your data in a portable, machine-readable format.
  • Withdraw consent at any time where we relied on it.
  • Complain to the UK Information Commissioner's Office (ICO) at ico.org.uk.

To exercise any of these rights, email support@varazm.com. We will respond within one month.

10

Security

We protect your data with appropriate technical and organisational measures, including HTTPS/TLS encryption in transit, encryption at rest, parameterised database access, Postgres row-level security, rate-limiting on sensitive endpoints, breach-checked passwords, two-factor authentication for staff accounts, regular backups and least-privilege access controls. No system is ever 100% secure, but we treat security as a continuous priority.

11

Cookies

We use a minimal set of strictly necessary first-party cookies to make the website work (for example, to remember your language, session and basic preferences). We do not use advertising cookies. You can block or delete cookies through your browser settings; some parts of the site may not work correctly without them.

12

Children

Our services are intended for businesses and adults. We do not knowingly collect personal data from children under 16. If you believe a child has provided us with personal data, please contact us and we will delete it.

13

Changes to this policy

We may update this Privacy Policy from time to time to reflect changes in our services or the law. Material changes will be highlighted on this page, and the "Last updated" date will always show the current version.

14

Contact us

For privacy questions, data requests or complaints please contact us at support@varazm.com. We aim to reply within 2 business days.

Frequently asked questions

What personal data does Varazm collect?
Only what a service needs: your name and contact details, order and billing information, and technical logs used to keep the site secure and working.
How do I request deletion of my data?
Email support@varazm.com from the address we hold for you. We confirm the request, delete what we are not legally required to retain, and reply once it is done.